Tuteliq helps platforms meet child safety obligations across jurisdictions. Here's exactly what we cover, and how.
Quick Compliance Checklist
At a glance, the regulations and standards Tuteliq helps you address.
Regulation-by-Regulation Breakdown
Detailed coverage for each regulation, what it requires and how Tuteliq helps you comply.
KOSA. Kids Online Safety Act (pending)
KOSA is not law. It would require platforms to prevent and mitigate harms to minors, including bullying, exploitation, and promotion of self-harm, but the text is still moving between the House and the Senate. Treat this as readiness work, not compliance.
HOW TUTELIQ HELPS
- Real-time detection of grooming, bullying, self-harm, and unsafe content across 7 risk categories
- Age-appropriate design tooling via API-driven risk scoring
- Parental notification support through configurable webhooks
- Audit-ready incident logs with full traceability
- 1.1-1.5s typical response times for proactive, not reactive, moderation
- Coverage that already satisfies obligations in force today under the DSA, the UK Online Safety Act, COPPA and the state design codes
COPPA. Children's Online Privacy Protection Act
COPPA regulates the collection and use of personal information from children under 13, requiring verifiable parental consent and data minimization.
- No child PII stored. Tuteliq analyses text content, not identities
- Data minimization by design: only message content is processed, never stored beyond analysis
- Configurable data retention and deletion via API
- Parental control hooks for consent workflows
- Full DPA available for COPPA-aligned data processing
EU Digital Services Act (DSA)
The DSA imposes obligations on platforms to protect users, especially minors, from illegal and harmful content, with transparency reporting and swift content actioning.
- Automated content classification aligned with DSA illegal content categories
- Transparency-ready: every API call returns structured risk assessments with confidence scores
- Incident reporting with timestamps and audit trails for DSA Article 16 notices
- Systematic risk assessment support (DSA Article 34) via aggregated analytics
- Content moderation evidence for trusted flagger and law enforcement cooperation
UK Online Safety Act
The UK OSA requires platforms to conduct risk assessments and implement safety measures to protect children from harmful content, with Ofcom as the regulator.
- Risk assessment evidence through structured incident classification
- Proactive content scanning covering all priority harmful content categories for children
- Age estimation support and age-appropriate content filtering
- Record-keeping and compliance evidence generation
- Rapid response: detection and alerting within milliseconds of content submission
GDPR & UK GDPR
GDPR governs how personal data is collected, processed, and stored, with strict requirements for lawful processing, data subject rights, and cross-border transfers.
- EU-based infrastructure, data never leaves the EU
- Privacy by design: no PII storage, content analysed in-memory only
- Full Data Processing Agreement (DPA) available
- Data subject access request (DSAR) support
- Right to erasure: no persistent data to delete
- Lawful basis documentation and processing records
AADC. Age Appropriate Design Code
The AADC (also known as the Children's Code) requires services likely to be accessed by children to provide age-appropriate experiences with high privacy defaults.
- Risk-scored content analysis to enforce age-appropriate experiences
- Default-high privacy: no profiling, no data retention
- Best-interests assessment support through structured risk categories
- Nudge and dark-pattern detection aligned with AADC principles
- Configurable sensitivity thresholds per age group
Security & Certifications
Enterprise-grade infrastructure you can trust.
GDPR Compliant
Built to meet EU and UK data protection requirements.
EU Data Residency
All data processed and stored within EU borders. No transatlantic transfers.
Zero content retention
No evaluation content is ever stored. Fully stateless, privacy-first architecture.
End-to-End Encryption
AES-256-GCM encryption for all sensitive data in transit and at rest.
99.99% Uptime SLA
Enterprise-grade availability with redundancy and failover.
How to prepare your platform for child safety regulation
A five-step path to evidencing child safety duties under the UK Online Safety Act, the EU Digital Services Act, COPPA, and GDPR.
- 1 Run a children's risk assessment Document which harms your service can expose children to, how likely they are, and what mitigations exist today. This assessment is the record regulators ask for first.
Run a children's risk assessment
Document which harms your service can expose children to, how likely they are, and what mitigations exist today. This assessment is the record regulators ask for first.
- 2 Determine which duties apply Establish where your users are and whether children can access your service, then map the applicable frameworks: UK Online Safety Act, EU Digital Services Act, COPPA, GDPR and Article 8, and any state-level requirements.
Determine which duties apply
Establish where your users are and whether children can access your service, then map the applicable frameworks: UK Online Safety Act, EU Digital Services Act, COPPA, GDPR and Article 8, and any state-level requirements.
- 3 Put proportionate detection in place Deploy detection for the harms your risk assessment identified, with thresholds calibrated to the ages of your users, and age assurance where a duty requires it.
Put proportionate detection in place
Deploy detection for the harms your risk assessment identified, with thresholds calibrated to the ages of your users, and age assurance where a duty requires it.
- 4 Define reporting and escalation Set out who reviews flagged content, how users report harm, how quickly you respond, and when law enforcement or a hotline is notified.
Define reporting and escalation
Set out who reviews flagged content, how users report harm, how quickly you respond, and when law enforcement or a hotline is notified.
- 5 Keep audit-ready evidence Retain incident logs, audit trails, your data processing agreement, the subprocessor list, and transparency reporting so your measures can be evidenced on request.
Keep audit-ready evidence
Retain incident logs, audit trails, your data processing agreement, the subprocessor list, and transparency reporting so your measures can be evidenced on request.
Frequently asked questions
Need a Compliance Deep-Dive?
Our team can walk you through how Tuteliq maps to your specific regulatory requirements. We also provide custom DPAs, security questionnaires, and compliance documentation.
Request a demo or compliance assessment
Tell us about your platform and we will map Tuteliq to your compliance duties within one business day.
By submitting, you agree to be contacted by Tuteliq about this request. We do not share your details with third parties.